CMMC Assessment Checklist
Download our CMMC assessment checklist!
Quick Answer: On July 13, 2026, the DoW paused CMMC Phase 2—the requirement for third-party C3PAO certification as a condition of contract award, originally set for November 10, 2026. Phase 1 self-assessments remain mandatory, existing certifications retain full value, and DFARS cybersecurity obligations are unchanged. Smithers will continue conducting assessments and is allowing rescheduling without penalty or fee.
The announcement came without warning—and for many defense contractors preparing for the November 10, 2026 deadline, it raised more questions than it answered. On July 13, 2026, DoW Chief Information Officer Kirsten Davies signed a policy memorandum (publication case 26-P-1023) pausing Phase 2 of the Cybersecurity Maturity Model Certification (CMMC) program and launching a 60-day, top-to-bottom review.
This is not a rollback of CMMC. It is not a reprieve from cybersecurity obligations. Understanding exactly what changed—and what did not—is essential for every contractor in the Defense Industrial Base.
The CMMC Phase 2 Pause specifically pauses the requirement for Organizational Seeking Certification (OSCs) to obtain a Level 2 certification from an accredited C3PAO as a condition of contract award. This requirement had been scheduled to take effect on November 10, 2026. Along with Phase 2, all pending and future CMMC implementation milestones—including Phases 3 and 4—are frozen until further notice.
The driving forces behind the pause were cost and capacity, from small businesses' perspective.
The CMMC Reform Task Force, reporting to the DoW CIO, has been charged with recommending a revised framework within 60 days. Industry stakeholders can submit responses to a public Request for Information (RFI) through August 14, 2026.
The pause is a policy memo—not a regulatory amendment. Several critical requirements remain fully in effect:
One critical nuance: the CMMC Phase 2 Pause binds DoW personnel, not your prime contractor's subcontract terms. DFARS 252.204-7021(f) requires primes to flow down the substance of the clause. Several primes have already indicated they will continue requiring C3PAO certifications for their supply chains, regardless of the DoW-level suspension. Confirm any changes to your flow downs in writing before altering your assessment plans.
If your organization has already obtained a Level 2 CMMC certificate, that certification loses none of its value—in fact, it gains value. As of the Cyber AB's May 2026 town hall, 1,391 Final Level 2 certificates had been issued. Nothing in the suspension invalidates them.
Under DFARS 252.204-7021(d)(1)(i), a Level 2 (C3PAO) status satisfies any lesser designation during the suspension. This means a completed certification still qualifies your organization for contract award at any applicable level. Certification also remains a differentiator with prime contractors and in merger and acquisition due diligence.
Smithers will continue to conduct CMMC assessments and issue certificates during this pause for clients who want to be CMMC certified. We recognize the disruption this announcement created, and we are responding accordingly.
All currently scheduled assessments may be rescheduled or delayed without penalty or fee. We remain available to answer any CMMC status or compliance questions during this period.
It is worth noting that your CMMC preparation costs have already been incurred. Your assessment costs remain future expenses—and proceeding with certification now carries real strategic advantage when your competitors pause or disengage from the process.
If your organization decides to defer its Level 2 C3PAO certification, do not treat the suspension as permission to stand down from cybersecurity work. Take the following steps:
If your organization has already initiated a C3PAO assessment, those records document your compliance posture and survive the suspension.
The Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) has suspended Level 3 inspections per the CIO's memorandum. Smithers expects DIBCAC to redirect those resources toward conducting SPRS Level 2 confirmation assessments of OSCs—a development that raises, rather than lowers, the stakes of maintaining an accurate and well-documented SPRS score.
Three developments warrant close attention:
The CMMC Phase 2 Pause is a speed bump, not a stop sign. The underlying legal framework—32 C.F.R. Part 170, DFARS cybersecurity clauses, and SPRS obligations—remains in force. Organizations that maintain compliance momentum, accurate documentation, and a defensible SPRS score will be better positioned regardless of how the CMMC program is ultimately reformed.
Smithers remains committed to supporting your CMMC readiness throughout this period. Contact our team with any questions about your current compliance status, assessment options, or what this pause means for your specific contracts.
If you have any questions or concerns, please reach out to us anytime, to learn more.
No. NIST SP 800-171 compliance remains required under DFARS 252.204-7012 for all contractors handling CUI. The pause suspends Phase 2 third-party certification requirements only—it does not change underlying cybersecurity obligations.
Yes. The Cyber AB confirmed on July 13, 2026: C3PAOs remain authorized to conduct Level 2 assessments and issue CMMC certificates in eMASS for publication to SPRS. Voluntary certification is fully available and retains significant contractual value.
Yes. As of May 2026, 1,391 Final Level 2 certificates had been issued, and none are invalidated by the suspension. A Level 2 (C3PAO) status satisfies any lesser designation under DFARS 252.204-7021(d)(1)(i).
Yes. Annual SPRS affirmations are still required under Phase 1, which went into effect in November 2025 and is unaffected by the Phase 2 suspension. Submitting a false or unsupported affirmation carries civil and criminal damages under the DOJ's Civil Cyber-Fraud Initiative.
Potentionally. Several prime contractors have indicated they will continue requiring C3PAO certifications for their supply chains. The DoW suspension binds DoW personnel, not prime contractor subcontract terms. Confirm requirements in writing with each customer before changing your assessment plans.
The DoW has not stated a fixed end date. The CMMC Reform Task Force is expected to deliver its recommendations to the DoW CIO in mid-September 2026.
The RFI comment period closes on August 14, 2026. Contractors who wish to provide cost data or compliance burden feedback should submit responses through the official SAM.gov posting before that date.